Ransomware Statistics 2024: A Complete Review (Updated 2026)
Ransomware in 2024 was defined by a striking paradox: attack volumes hit record highs while ransom payments dropped sharply.
Table of Contents
Ransomware in 2024 was defined by a striking paradox: attack volumes hit record highs while ransom payments dropped sharply. Threat actors launched at least 5,263 ransomware attacks worldwide, the highest annual total since monitoring began, according to the NCC Group Annual Cyber Threat Monitor Report published in January 2025. Yet victims paid roughly 35% less than the year before, with total cryptocurrency payments landing at $892 million per the Chainalysis 2026 Crypto Crime Report. This article compiles the most important ransomware statistics from 2024, drawn exclusively from reports published in 2025 and 2026, and traces how the threat has continued to evolve since then.
Key Ransomware Statistics From 2024
5,263 ransomware attacks were recorded globally in 2024, the highest annual volume on record (NCC Group, January 2025)
$892 million in cryptocurrency ransomware payments were collected by attackers in 2024 (Chainalysis, February 2026)
44% of all data breaches involved ransomware, up from 32% the prior year (Verizon 2025 DBIR)
88% of SMB breaches involved ransomware, compared to 39% at larger organizations (Verizon 2025 DBIR)
64% of victims refused to pay the ransom, up from 50% two years earlier (Verizon 2025 DBIR)
$115,000 was the median ransom payment, down from $150,000 in the prior reporting period (Verizon 2025 DBIR)
$3.12 million was the mean recovery cost per ransomware incident in 2024 (Sophos State of Ransomware 2025)
66% of ransomware attacks resulted in successful data encryption (Sophos State of Ransomware 2025)
$1.26 million was the median ransom payment among organizations that did pay (Sophos State of Ransomware 2025)
Ransomware complaints to the FBI rose 9% from 2023 levels, and ransomware remained the top threat to critical infrastructure (FBI IC3 2024 Annual Report, released 2025)
Record Attack Volume Despite Law Enforcement Pressure
The 5,263 attacks tracked by NCC Group in 2024 represented a meaningful increase over the prior year, even as international law enforcement landed significant blows against major ransomware operations. The takedown of LockBit infrastructure in February 2024 disrupted the group's operations but did not remove it from the landscape entirely. NCC Group still attributed 526 attacks, or 10% of the annual total, to LockBit affiliates. RansomHub emerged as the dominant threat actor in the second half of the year, claiming 501 attacks and filling much of the vacuum left by LockBit's disruption.
The geographic concentration of attacks remained heavily skewed toward Western economies. North America absorbed over 55% of all recorded ransomware incidents, and when combined with Europe, that share rose to 79%. However, NCC Group noted rising activity in Asia, South America, and Oceania, signaling that ransomware operators were broadening their target base.
The industrial sector bore the heaviest burden, accounting for 27% of all attacks (1,424 incidents) and experiencing a 15% year-over-year increase. Manufacturers, utilities, and logistics companies are especially vulnerable because operational downtime directly translates into financial pressure to pay, making them high-value targets for extortion.
The Payment Paradox: More Attacks, Less Revenue
One of the most encouraging ransomware statistics from 2024 is the sharp decline in payments. According to the Chainalysis 2026 Crypto Crime Report, total on-chain ransomware payments fell to $892 million in 2024 after peaking at roughly $1.37 billion in 2023. That 35% drop happened even as attack volumes climbed, pointing to a meaningful shift in how organizations respond to ransomware incidents.
The Verizon 2025 DBIR reinforced this trend. Among the breaches it analyzed during the November 2023 to October 2024 reporting window, 64% of victim organizations declined to pay, compared to 50% just two years earlier. The median payment among those who did pay dropped to $115,000, down from $150,000 in the prior period.
Several factors drove the payment decline. Improved backup strategies meant more organizations could recover without the decryption key. The FBI distributed thousands of decryption keys to ransomware victims, helping organizations avoid over $800 million in potential payments since 2022. And growing awareness that payment does not guarantee data recovery, nor prevent future attacks, shifted the calculus for many leadership teams.
That said, the picture was not uniformly positive. Sophos found that among organizations surveyed for its State of Ransomware 2025 report, the median ransom payment reached $1.26 million, and median demands hit $2.75 million. The gap between the Verizon and Sophos figures reflects differences in methodology and sample composition, but both reports agree on the directional trend: fewer organizations are paying, yet those that do are paying substantial sums.
Small Businesses in the Crosshairs
Perhaps the most alarming finding in the 2024 data is the outsized impact on small and medium-sized businesses. The Verizon 2025 DBIR found that ransomware was present in 88% of breaches affecting SMBs, compared to 39% at larger organizations. That gap is enormous, and it reflects a structural disadvantage: smaller companies typically lack dedicated security teams, 24/7 monitoring, and the incident response playbooks that larger enterprises maintain.
The financial impact compounds the problem. Recovery costs averaging $3.12 million, as reported by Sophos, can be existential for a company with $10 million or $20 million in annual revenue. Downtime, lost business, regulatory penalties, and reputational damage pile on top of the direct costs of remediation. For many SMBs, a ransomware attack is not just a security event but a business survival event.
The encryption rate adds another dimension. Sophos found that 66% of ransomware attacks in 2024 successfully encrypted the victim's data. While that figure was lower than in prior years, suggesting that detection and response capabilities are improving, it still means that two-thirds of targeted organizations lost access to their files. Organizations that relied on backups for recovery reported using them in 73% of cases, underscoring the importance of robust, tested, and isolated backup systems.
The Rise of Dual Extortion and Data Theft
By 2024, pure encryption attacks had become the exception rather than the rule. Most ransomware operators adopted dual-extortion tactics, combining file encryption with data theft and the threat of public exposure on leak sites. This evolution means that even organizations with perfect backups face the risk of sensitive data being published or sold.
The NCC Group report documented a steady increase in leak-site postings throughout 2024, with threat actors using data exposure as leverage regardless of whether the victim could restore systems from backups. The tactic is especially damaging in regulated industries such as healthcare and financial services, where data exposure triggers mandatory breach notifications, regulatory investigations, and potential fines.
Sophos reported that the median ransom demand of $2.75 million in 2024 often reflected the perceived value of stolen data as much as the cost of operational disruption. Attackers increasingly priced their demands based on the sensitivity of exfiltrated files, revenue of the victim organization, and the potential regulatory consequences of a data leak.
How Numbers Evolved in 2025-2026
The trends visible in the 2024 data have intensified. The Chainalysis 2026 report shows that total ransomware payments fell further to $820 million in 2025, an 8% decline from the revised 2024 figure, while the share of victims who paid potentially reached an all-time low of 28%. Interestingly, the median payment climbed 368% to $59,556, suggesting that opportunistic small-dollar payments dried up while a smaller number of high-value targets accounted for a larger share of the total.
The Verizon 2026 DBIR found ransomware present in 48% of breaches, up from 44% in the 2025 edition, continuing the upward trajectory. NCC Group's data for 2025 showed another record year for global ransomware volume. And the FBI's IC3 2025 report logged 3,611 ransomware complaints with $32.3 million in reported losses, up from 3,156 complaints and $12.5 million in 2024.
The ransomware ecosystem has also fragmented. Dozens of new groups entered the space in 2025 and 2026, and the collapse of established brands like LockBit and ALPHV/BlackCat created openings that smaller, more agile operators quickly filled. The barrier to entry continues to drop as ransomware-as-a-service platforms make sophisticated tools available to less technically skilled affiliates.
Recovery costs have begun to decline modestly. Sophos reported mean recovery costs falling from $3.12 million in 2024 to $1.84 million in 2025, driven in part by faster detection and better-prepared incident response processes. But the overall trend remains clear: ransomware is becoming more frequent, more distributed across threat actors, and more difficult to defend against without dedicated security resources.
How Managed IT Services Can Help
The ransomware statistics from 2024 make a compelling case for proactive, professionally managed security. With 88% of SMB breaches involving ransomware and mean recovery costs exceeding $3 million, the risk of operating without dedicated security resources has never been higher.
Managed IT services providers address the exact vulnerabilities that ransomware operators exploit. Continuous monitoring catches suspicious activity before encryption begins. Managed endpoint detection and response tools can isolate compromised machines in seconds. Regular patch management closes the known vulnerabilities that threat actors use for initial access. And tested, isolated backup systems ensure that organizations can recover without paying a ransom.
For small and medium-sized businesses that cannot justify building an in-house security operations center, a managed IT services partner provides enterprise-grade protection at a fraction of the cost. The 2024 data is unambiguous: organizations that invest in layered defenses, rapid detection, and professional incident response are far more likely to survive a ransomware attack with their business intact.
Related Articles
- Third-Party Data Breach Statistics for 2026Third-party data breaches now account for nearly half of all confirmed breaches worldwide. According to the 2026 Verizon Data Breach Investigations Report, 48% of breaches involved a third-party…
- Small Business Ransomware Statistics for 2026Ransomware has become the defining cyber threat for small businesses. According to the Verizon 2026 Data Breach Investigations Report, ransomware now appears in 48% of all breaches analyzed, up from…
- Small Business Cybersecurity Statistics for 2026Small businesses face an unprecedented wave of cyber threats in 2026. According to the Hiscox Cyber Readiness Report 2026, 56% of U.S.
- Shadow IT Statistics for 2026: What the Latest Data RevealsShadow IT, the use of technology, software, and cloud services without IT department approval, continues to grow as one of the most persistent security and compliance challenges facing…
Hadley McIntosh
Updated Sep 26, 2026 · 8 min read